๐บ๐ธ
209.132.174.144
16 Sep 2026
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity
Port Scan
๐ณ๐ฑ
213.177.179.171
16 Sep 2026
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity | ...
show more
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity | Evidence: Repeat-Offender (Past Bans: 2)
show less
Port Scan
๐บ๐ธ
35.232.243.75
16 Sep 2026
Detectors: [NGINX] | Reasons: Nginx Honeypot: Sensitive configuration file search | Evidence: High-C ...
show more
Detectors: [NGINX] | Reasons: Nginx Honeypot: Sensitive configuration file search | Evidence: High-Criminality-Signature (ja4:t13d4312h1 - Ratio:0.99), High-Criminality-Signature (ja4h:fcf4aea274ba962cd9aab32b28f97e0a - Ratio:0.94), OS-Signature-Mismatch (UA:Windows/p0f:Linux) | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | TCP Fingerprint: Linux (Legacy/Embedded) (Link:generic tunnel or VPN, Uptime:61756m)
show less
Hacking
Web App Attack
๐ณ๐ฑ
213.177.179.154
16 Sep 2026
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity
Port Scan
๐ฆ๐ท
45.191.85.192
16 Sep 2026
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity
Port Scan
๐จ๐ณ
106.63.26.14
16 Sep 2026
Detectors: [NGINX] | Reasons: Nginx: Repeat offender returning to default/inactive vhost after previ ...
show more
Detectors: [NGINX] | Reasons: Nginx: Repeat offender returning to default/inactive vhost after previous ban | Evidence: Repeat-Offender (Past Bans: 2) | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36 Edg/120.0.0.0 | TCP Fingerprint: Linux (Legacy/Embedded) (Link:generic tunnel or VPN, Uptime:0m)
show less
Port Scan
Web App Attack
๐จ๐ณ
106.63.26.20
16 Sep 2026
Detectors: [NGINX, nginx_monitor] | Reasons: Invalid HTTP protocol or SSTP scan attempt detected on ...
show more
Detectors: [NGINX, nginx_monitor] | Reasons: Invalid HTTP protocol or SSTP scan attempt detected on sinkhole | Evidence: Repeat-Offender (Past Bans: 1) | TCP Fingerprint: Linux (Legacy/Embedded) (Link:generic tunnel or VPN, Uptime:0m)
show less
Port Scan
๐บ๐ธ
35.196.194.248
16 Sep 2026
Detectors: [NGINX, SURICATA] | Reasons: Suricata: Web Server attack | Automated scan targeting an un ...
show more
Detectors: [NGINX, SURICATA] | Reasons: Suricata: Web Server attack | Automated scan targeting an unauthorized host or default server sinkhole | Evidence: Verified-Bot-JA4-Match (t13d1516h2) | TCP Fingerprint: Modern Linux (Kernel 3.x+) (Link:generic tunnel or VPN, Uptime:0m)
show less
Web App Attack
Hacking
Port Scan
Bad Web Bot
๐ฎ๐ณ
182.71.75.106
16 Sep 2026
Detectors: [NGINX] | Reasons: Nginx Honeypot: Sensitive configuration file search | Evidence: Truste ...
show more
Detectors: [NGINX] | Reasons: Nginx Honeypot: Sensitive configuration file search | Evidence: Trusted-JA4-Signature (t13d131000), Trusted-P0F-Signature (*:64:0:*:mss*44,7:mss,sok,ts,nop,ws:df,id+:0), OS-Signature-Mismatch (UA:Windows/p0f:Linux) | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 | TCP Fingerprint: Linux (Legacy/Embedded) (Link:PPPoE, Uptime:58440m)
show less
Hacking
Web App Attack
๐ต๐ฐ
153.117.40.213
15 Sep 2026
Detectors: [NGINX, nginx_monitor] | Reasons: Invalid HTTP protocol or SSTP scan attempt detected on ...
show more
Detectors: [NGINX, nginx_monitor] | Reasons: Invalid HTTP protocol or SSTP scan attempt detected on sinkhole | Evidence: High-Criminality-Signature (p0f:*:64:0:*:mss*10,5:mss,sok,ts,nop,ws:df,id+:0 - Ratio:0.96) | TCP Fingerprint: Modern Linux (Kernel 3.x+) (Link:IPIP or SIT, Uptime:0m)
show less
Port Scan
๐ฉ๐ช
5.252.26.87
15 Sep 2026
Detectors: [NGINX, nginx_monitor] | Reasons: Nginx: Default server trap hit | Invalid HTTP protocol ...
show more
Detectors: [NGINX, nginx_monitor] | Reasons: Nginx: Default server trap hit | Invalid HTTP protocol or SSTP scan attempt detected on sinkhole | Evidence: URL-Found-In-UA | UA: Mozilla/5.0 (Windows NT 10.0; rv:132.13) Gecko/20100101 Firefox/132.13; compatible; OAI-SearchBot/1.3; +https://openai.com/searchbot | TCP Fingerprint: Android 10 or newer (Link:PPPoE, Uptime:0m)
show less
Port Scan
Exploited Host
๐น๐ผ
45.43.37.254
15 Sep 2026
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity | ...
show more
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity | Evidence: Persistent-Slow-Scanner (Strikes: 7), Repeat-Offender (Past Bans: 6)
show less
Port Scan
๐บ๐ธ
34.59.124.148
15 Sep 2026
Detectors: [NGINX, SURICATA] | Reasons: Suricata: Web Server attack | Automated scan targeting an un ...
show more
Detectors: [NGINX, SURICATA] | Reasons: Suricata: Web Server attack | Automated scan targeting an unauthorized host or default server sinkhole | Evidence: Verified-Bot-JA4-Match (t13d1516h2) | TCP Fingerprint: Modern Linux (Kernel 3.x+) (Link:generic tunnel or VPN, Uptime:0m)
show less
Web App Attack
Hacking
Port Scan
Bad Web Bot
๐บ๐ธ
144.172.89.127
15 Sep 2026
Detectors: [NGINX] | Reasons: Nginx Honeypot: Sensitive configuration file search | Evidence: Verifi ...
show more
Detectors: [NGINX] | Reasons: Nginx Honeypot: Sensitive configuration file search | Evidence: Verified-Bot-JA4-Match (t13d131100), Trusted-JA4-Signature (t13d131100), Trusted-P0F-Signature (*:64:0:*:mss*44,7:mss,sok,ts,nop,ws:df,id+:0), High-Criminality-Signature (ja4h:c308f84e3b7796240a9cfa5ec1c6880f - Ratio:1.00), Repeat-Offender (Past Bans: 2) | UA: Mozilla/5.0 (X11; Linux x86_64) | TCP Fingerprint: Linux (Legacy/Embedded) (Link:PPPoE, Uptime:0m)
show less
Hacking
Web App Attack
๐ณ๐ฑ
213.177.179.160
15 Sep 2026
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity | ...
show more
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity | Evidence: Repeat-Offender (Past Bans: 2)
show less
Port Scan
๐ณ๐ฑ
213.177.179.179
15 Sep 2026
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity | ...
show more
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity | Evidence: Repeat-Offender (Past Bans: 2)
show less
Port Scan
๐ช๐ธ
45.92.85.94
15 Sep 2026
Detectors: [NGINX] | Reasons: Nginx: Repeat offender returning to default/inactive vhost after previ ...
show more
Detectors: [NGINX] | Reasons: Nginx: Repeat offender returning to default/inactive vhost after previous ban | Evidence: Trusted-P0F-Signature (*:64:0:*:65535,9:mss,sok,ts,nop,ws:df,id+:0), Repeat-Offender (Past Bans: 1) | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.61 Safari/537.36 | TCP Fingerprint: Android 10 or newer (Link:PPPoE, Uptime:41759m)
show less
Port Scan
Web App Attack
๐ฟ๐ฆ
102.217.42.91
15 Sep 2026
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity
Port Scan
๐ช๐ธ
45.92.84.180
15 Sep 2026
Detectors: [NGINX] | Reasons: Nginx: Repeat offender returning to default/inactive vhost after previ ...
show more
Detectors: [NGINX] | Reasons: Nginx: Repeat offender returning to default/inactive vhost after previous ban | Evidence: Trusted-P0F-Signature (*:64:0:*:65535,9:mss,sok,ts,nop,ws:df,id+:0), Repeat-Offender (Past Bans: 1) | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.61 Safari/537.36 | TCP Fingerprint: Android 10 or newer (Link:PPPoE, Uptime:25281m)
show less
Port Scan
Web App Attack
๐บ๐ธ
34.106.226.124
15 Sep 2026
Detectors: [NGINX] | Reasons: Nginx Honeypot: Sensitive configuration file search | Evidence: High-C ...
show more
Detectors: [NGINX] | Reasons: Nginx Honeypot: Sensitive configuration file search | Evidence: High-Criminality-Signature (ja4:t13d4312h1 - Ratio:0.98), High-Criminality-Signature (ja4h:33f56baf5bd7a8c6c1fc8c4c9a1d4829 - Ratio:0.94) | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | TCP Fingerprint: Linux (Legacy/Embedded) (Link:generic tunnel or VPN, Uptime:28372m)
show less
Hacking
Web App Attack
๐บ๐ฆ
194.60.254.68
15 Sep 2026
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity
Port Scan
๐ฏ๐ต
45.43.60.98
15 Sep 2026
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity
Port Scan
๐ณ๐ฑ
45.148.10.212
15 Sep 2026
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity
Port Scan
๐ธ๐ฌ
129.121.128.70
15 Sep 2026
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity | ...
show more
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity | Evidence: Repeat-Offender (Past Bans: 1)
show less
Port Scan
๐จ๐ณ
120.211.138.165
15 Sep 2026
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity | ...
show more
Detectors: [pfsense_monitor] | Reasons: Firewall: Prohibited Port Scan / Automated Botnet Activity | Evidence: Repeat-Offender (Past Bans: 1)
show less
Port Scan